Description
An unencrypted 'pause encryption request' message causes a denial of service in the in the RS9116W/SiWx917. See vulnerability B-E10 in the related paper below.
Published: 2026-09-08
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The RS9116W/SiWx917 wireless chip can be made to become unresponsive to normal traffic when it receives an unencrypted "pause encryption request" packet. The vulnerability is a case of insufficient access control, which allows an attacker to trigger a denial‑of‑service, damaging availability but not confidentiality or integrity.

Affected Systems

The weakness affects the Silabs WiseCnnect product line that incorporates the RS9116W or SiWx917 radio ASIC. No specific firmware or hardware revisions are listed, meaning all devices that use those chips are vulnerable until a patch is deployed.

Risk and Exploitability

The CVSS base score of 7.1 shows high severity, yet the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating limited evidence of widespread exploitation. Attackers would need to deliver the malformed pause encryption request to the target device; the description implies the packet must reach the radio controller, so the likely vector is via the device’s wireless interface or a connected wired interface. If an adversary can transmit such packets, the device will cease normal operation, causing a denial of service to all applications relying on the chip.

Generated by OpenCVE AI on September 8, 2026 at 18:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Silabs firmware that contains a fix for the unencrypted pause encryption request DoS.
  • If firmware cannot be updated, reconfigure the device to reject or ignore pause encryption requests, or to enforce encryption on command channels.
  • Deploy network filtering or rate‑limiting on the device’s wireless or wired interface to mitigate repeated malformed requests.

Generated by OpenCVE AI on September 8, 2026 at 18:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Silabs.com
Silabs.com wiseconnect
Vendors & Products Silabs.com
Silabs.com wiseconnect

Tue, 08 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description An unencrypted 'pause encryption request' message causes a denial of service in the in the RS9116W/SiWx917. See vulnerability B-E10 in the related paper below.
Title RS9116W/SiWx917 plaintext pause encryption request causes DOS
Weaknesses CWE-440
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Silabs.com Wiseconnect
cve-icon MITRE

Status: PUBLISHED

Assigner: Silabs

Published:

Updated: 2026-09-08T18:09:00.788Z

Reserved: 2026-07-23T15:53:43.587Z

Link: CVE-2026-16769

cve-icon Vulnrichment

Updated: 2026-09-08T18:08:52.600Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T16:18:03.677

Modified: 2026-09-08T19:17:51.163

Link: CVE-2026-16769

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T19:00:13Z

Weaknesses
  • CWE-440

    Expected Behavior Violation